State Warns Employees of Malware -- from Newspaper Ads

slfisher 2 Tallied Votes 492 Views Share

It's not unusual for a government IT department to warn its users about downloading malware onto their government-issued computers. It's more unusual, though, for the source of the malware to be the ads on the website of the newspaper of record.

In July, the cyber security coordinators in the state of Idaho took the unusual step of recommending that its users block or avoid the website of the Idaho Statesman, a Boise-based daily paper that covers most of the state, due to what was said to be malware in the website's ads, according to a memo sent to the security team.

Upon presumably reporting the problem to the paper, the paper began scanning the ads for malware before placing them on the site, and the state IT department also looked for malware in the paper's ads.

"Therefore, since there are many agencies or individual employees who must access the Idaho Statesman, their business needs must be met; particularly since the overall risk seems to have returned to a normal, cautious state. I no longer recommend blocking or avoiding the Idaho Statesman website, though anyone who does should be cautious," the memo continued, which alluded to a similar incident in as well. (Boise State University, which is funded by the state, a similar incident in December, 2009.)

"The Statesman is not alone in having issues with malware; many local and national news sites (including the New York Times and the Seattle Times) have had to deal with this in the past or are currently working on the same problem," the paper said in a note on the January incident.

State employees were also encouraged to implement ad-blocking software, because malware can be hidden in many website ads, to use a web filter that looks for malware in ads and, without those, not clicking on things.

Users were warned that they did not need to click on the ads for the malware to be effective.

Dani AI

Generated

Good points from and — this thread highlights a classic and persistent risk: malicious code delivered through legitimate-looking ads (malvertising). Attacks can run as soon as ad content is loaded or when an ad redirects to an exploit page, so treating ad inventory the same way you treat unknown sites is prudent. (malwarebytes.com)

How it typically works: bad or hijacked ad creatives flow through real ad networks or third-party supply chains, then use hidden iframes, redirect chains or exploit kits to push drive‑by downloads at unpatched browsers and plugins. Programmatic ad delivery widened the attack surface because one compromised creative can reach many publishers quickly. (securityweek.com)

Practical, immediate steps for IT/security teams:

  • Standardize and harden supported browsers, force updates, and remove unused plugins.
  • Enable click‑to‑play or disable legacy plugins (Flash/Java) and use least‑privilege user accounts.
  • Route high‑risk browsing through browser isolation or a disposable VM.
  • Deploy protective DNS / enterprise web‑filtering and EDR so malicious domains and post‑infection activity are stopped quickly.
  • If using ad‑blocking extensions, centrally vet solutions — extensions have broad privileges and can introduce risk if unmanaged.
    These are recommended defensive controls for organizations facing malvertising. (cisa.gov)

When a specific publisher is implicated, prefer targeted mitigations: block or sinkhole the ad domains, force staff to use an isolated session for required access, and require the publisher to scan and quarantine the offending creatives. Ad platforms and networks have stepped up enforcement and block large volumes of bad ads, but supply‑chain vetting and publisher cooperation remain essential. (blog.google)

Short, actionable posture: patch fast, minimize attack surface (fewer plugins, fewer browser variants), use network‑level protections (PDNS/web filters), and isolate risky browsing. That combination will reduce the chance that a single dodgy ad causes a desktop‑wide incident. (malwarebytes.com)

Member Avatar for Member #949455
Member #949455

Users were warned that they did not need to click on the ads for the malware to be effective.

Right now 2013, it's still happening across the country regarding telling employee not to click on ads to get malware.

In the end one or two employee by accident click the ad.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.